A precise, current definition of KYB (Know Your Business): what it verifies, the end-to-end process, what a UBO is, and how the US, UK, and EU rules differ in 2026, including the FinCEN CDD Rule versus Corporate Transparency Act distinction most guides get wrong.
Know Your Business (KYB), also called corporate KYC, is the process of confirming that a business is a real, legally registered entity, then identifying and verifying the real people who ultimately own and control it, its beneficial owners. It applies the anti-money-laundering due diligence that Know Your Customer applies to individuals, but to a legal entity, then traces through to the humans behind it.
Know Your Business (KYB) is the due diligence a regulated firm performs on a business customer or counterparty to confirm the entity is legitimate and to identify the natural persons behind it. It is frequently called corporate KYC, because it is the same customer due diligence discipline that anti-money-laundering law requires for individuals, extended to legal entities. A KYB check answers three questions: is this a real, legally registered entity? Who ultimately owns and controls it? And does the entity, or any of the people behind it, present a financial-crime risk?
Why it exists. A company is a legal fiction. It cannot be brought in for an identity check, and it can be layered inside other companies, trusts, and holding structures across several countries until nobody can see who is actually behind it. That opacity is the core money-laundering risk. Shell and front companies are the standard tool for hiding the origin and ownership of illicit funds, and FinCEN has long identified shell-company exploitation as a serious vulnerability in the US financial system, with one widely cited order-of-magnitude estimate putting the annual cost of shell-company abuse at around 70 billion US dollars. KYB exists to pierce that opacity: to establish that the entity is genuine, that its stated activity is real, and that the humans who ultimately benefit are not sanctioned, politically exposed in a way that raises risk, or otherwise disqualified.
The defining difference from KYC is the ownership problem. With an individual you verify one identity. With a business you verify the entity and then trace through it to the humans who benefit, because a company cannot be a beneficial owner of itself. That is why KYB requires registry and corporate-document checks, ownership-chain resolution, and the discovery of ultimate beneficial owners that a straight identity check never touches.
A modern KYB workflow runs in six stages. Competitor guides expand this to eight or ten steps, but the same logic sits underneath. The order matters: you establish the entity is real before you work out who is behind it, and you verify those people before you make a risk decision.
The order is not optional. Screening a company before you have resolved its owners misses the people who carry the risk, and risk-rating before screening produces a rating you cannot defend. For a practical walk-through of how each stage is done at scale, see how to verify a business.
A UBO is the natural person who ultimately owns or controls a legal entity, or on whose behalf a transaction is conducted. The concept is the point of KYB, because a corrupt or criminal actor rarely appears as the named owner. They sit behind holding companies, trusts, and nominee arrangements. Establishing who really benefits is what separates KYB from a superficial company check.
Ownership thresholds differ by regime, and this is a common point of confusion. In the US, under the FinCEN CDD Rule, a beneficial owner is any individual who owns 25 percent or more of the equity of a legal entity customer (the ownership prong), plus at least one individual with significant responsibility to control or manage the entity, such as a senior officer (the control prong). Every legal entity customer therefore resolves to between one and five beneficial owners. In the UK and EU the threshold is generally more than 25 percent of shares or voting rights, or control by other means. In the UK this is captured by the register of people with significant control (PSC).
The hardest part in practice is not the threshold, it is following the chain. If Company A is owned 60 percent by Company B, which is in turn owned 50 percent by an individual and 50 percent by a trust in another country, you have to compute effective ownership through the layers and verify people who may be in jurisdictions with weak or closed registries. This is where KYB becomes genuinely difficult, and where the UBO glossary page goes deeper on ownership-chain mechanics.
KYB obligations, or strong commercial reasons to perform KYB, apply across the regulated economy whenever a business is onboarded as a customer or counterparty.
Business onboarding is where speed and compliance collide. Corporate onboarding is slow, and the harder the ownership structure, the longer it takes. That friction is exactly what drives buyers toward automation and orchestration, and it is the problem the Zenoo KYB use case is built around.
A common FATF baseline sits under three blocs that are moving in different directions, and one of them, the US, reversed course dramatically in 2025. The FATF standard setter revised Recommendation 24 (beneficial ownership of legal persons) in March 2022 to require a multi-pronged approach so that adequate, accurate, and up-to-date beneficial-ownership information is available to authorities, and revised Recommendation 25 (legal arrangements, such as trusts) in February 2023, with updated risk-based guidance following in March 2024. By 2025 around 149 countries had implemented UBO verification requirements for regulated entities.
United States: two separate regimes, and a 2025 reversal. The FinCEN CDD Rule (2018) applies to banks and other covered financial institutions: when opening an account for a legal entity customer, they must identify and verify beneficial owners at the 25 percent ownership threshold plus one control person. Separately, the Corporate Transparency Act and FinCEN's beneficial-ownership information (BOI) reporting required companies themselves to file their beneficial owners into a central register. These are two different obligations. BOI reporting took effect on 1 January 2024, then a turbulent year of litigation followed: a nationwide injunction on 3 December 2024, a Supreme Court stay of that injunction on 23 January 2025, and finally, on 26 March 2025, a FinCEN interim final rule that removed BOI reporting obligations for all US-formed entities and US persons, redefining reporting company to cover only entities formed abroad and registered to do business in the US. The practical takeaway: the March 2025 rule gutted the company self-reporting register, but it did not remove banks' obligation to perform beneficial-ownership due diligence. The CDD Rule remains in force, so a bank onboarding a business still has to identify and verify UBOs itself. (This area is fast-moving: FinCEN issued further CDD Rule exceptive relief in February 2026 easing re-verification at every new account opening.)
United Kingdom: the PSC register and identity-verification reform. The UK's core KYB framework is the Money Laundering Regulations 2017 for the CDD obligation, sitting on top of Companies House and the register of people with significant control, which records individuals who hold more than 25 percent of shares or voting rights or otherwise control a company. The Economic Crime and Corporate Transparency Act 2023 is turning Companies House from a passive filing library into an active gatekeeper: its identity-verification requirements became mandatory on 18 November 2025, with directors, PSCs, and filers required to verify their identity, phased in over a 12-month transition for existing directors and PSCs, and civil penalties of up to 10,000 pounds for non-compliance.
European Union: harmonisation, plus the register-access swing. The EU's anti-money-laundering package, the Anti-Money Laundering Regulation (EU) 2024/1624 (AMLR), the sixth directive (AMLD6), and a new supervisor, the Anti-Money Laundering Authority (AMLA), applies directly and identically across all 27 member states from 10 July 2027. On UBO register access, under the fifth directive registers were open to the general public, but on 22 November 2022 the Court of Justice of the EU struck that down as a disproportionate interference with privacy and data-protection rights. AMLD6 re-establishes access on a legitimate-interest basis: competent authorities and obliged entities keep full access, and others, notably journalists and civil society working on AML, get access where a legitimate interest is shown. Member states had to guarantee legitimate-interest access by 10 July 2025, with full application by 10 July 2027.
KYC verifies an individual customer. KYB verifies a business customer, and then traces through to the individuals who own and control it. KYB is therefore KYC plus an ownership-and-control problem: you still end up verifying and screening natural persons, the UBOs and directors, but only after you have established that the entity is real and worked out who those people are.
The practical differences follow from that. KYB requires registry and corporate-document checks that KYC does not. KYB has to resolve ownership chains and apply thresholds. And KYB data ages in different ways: a director changes, a company is dissolved, an owner sells down below the threshold. This page owns the definition; the dedicated KYC vs KYB vs KYT comparison goes deeper on where each one fits.
Practitioners search what is KYB and then immediately hit these walls. Naming them honestly is what marks a KYB programme as built by people who have done the work.
AI has become the workhorse of KYB at scale, used defensively across the process. Models traverse corporate registries to map ownership networks and surface owners that manual review misses, cross-reference multiple data sources to discover associated persons, turn entity, country, and industry signals into risk scores, and pre-classify screening alerts so investigators see only what needs a human. Continuous monitoring, watching for a material change and re-triggering KYB automatically, is what makes perpetual review feasible at all. The honest framing: AI accelerates and de-noises the human work, it does not replace the decision. A person still signs off on whether an entity is cleared or escalated.
Ownership-network mapping and cross-source discovery let AI surface UBOs and associated persons that a manual reviewer, working one registry at a time, would miss. Alert pre-classification and drafted resolution notes cut the time spent reading, so analysts spend their judgement where it matters. The machine does the reading; the analyst keeps the decision.
The same technology is turned against KYB controls. Attackers generate synthetic and forged incorporation documents, fabricate plausible-looking company footprints, and industrialise fake business identities designed to pass onboarding. Because a business is verified through documents and registry data rather than a face, KYB is exposed to document forgery and to structures deliberately built to defeat automated checks.
The lesson mirrors the fraud side of KYC: no single detector holds, because attackers probe each one until it breaks. The honest defence is several independent checks across registries, UBO data, document verification, and screening, so one source's blind spot is covered by another. That is the case for orchestration rather than a single hard-wired vendor.
KYB is a multi-source problem, and that is exactly what orchestration is for. A complete KYB check on a cross-border company can touch a business-registry provider, a UBO or corporate-structure data provider, a document-verification vendor, and sanctions, PEP, and adverse-media screening, often across several jurisdictions. Most teams stitch these together themselves. The typical compliance team runs 6 to 8 disconnected tools, and the average institution uses about 4.7 verification providers.
Reframing KYB as an orchestration problem changes what a KYB programme should look for: not one vendor's coverage, but routing to the right source per jurisdiction, failover when a source is down, one place where ownership discovery, screening, and document checks meet, and a single audit trail across all of them. It also makes ongoing KYB, re-verification as ownership and status change, practical rather than aspirational. You can compare the sources that feed this in the Zenoo Marketplace, and the section below sets out honestly where Zenoo helps and where it does not.
KYB spans registries, UBO data, document checks, and screening across jurisdictions, which is exactly why it fragments across vendors. Zenoo is an orchestration layer: your KYB vendors plus Zenoo, not instead of them. It routes each check to the right provider for the jurisdiction, fails over when one is down, and brings registry and UBO discovery, screening, and document verification into one place with a single immutable audit trail (32 event types across 8 categories) so you can show a regulator why an entity or UBO was cleared or escalated. Zenoo does not publish its own registry or UBO dataset and does not fix thin underlying data. Its 10 specialised AI agents remove the manual research: the KYB Researcher compiles a 50-plus-field company dossier in under 60 seconds against a manual 2 to 4 hours, and the analyst keeps the decision.